component-validator
Warn
Audited by Snyk on Aug 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The runtime workflow reads a single component file provided by the parent/upsert flow (staged scratch
body.jsonor a fresh fetch from the branch viadxs source explore/configuration get), which an outsider can potentially author/submit, so the agent ingests outsider-authored free text/JSON before auditing.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The Sub-agent explicitly instructs the runtime to "load the matching rule document" (e.g. ../action-creator/references/actions.md), and those relative document paths are read at runtime and directly control the validator's checklist/prompts, so they are runtime external dependencies.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata